You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RabbitMQ SSL端口5671可telnet但EasyNetQ连接失败求助

Fixing "None of the specified endpoints were reachable" with EasyNetQ + RabbitMQ TLS

Let’s walk through the key issues in your code and setup that are almost certainly causing this connection failure, plus how to fix them step by step:

1. SSL Server Name Mismatch is a Critical Red Flag

Your code sets host1.Ssl.ServerName = "localhost"; — that’s incorrect. The SSL Server Name has to exactly match the Common Name (CN) or Subject Alternative Name (SAN) on the RabbitMQ server’s certificate. Since you’re connecting to skl-igor-naum1, this value needs to be that hostname (or whatever CN/SAN is listed on the server’s cert). If the server cert was issued to skl-igor-naum1, update this line to:

host1.Ssl.ServerName = "skl-igor-naum1";

A mismatch here breaks the SSL handshake entirely, which shows up as the vague "unreachable endpoints" error in EasyNetQ.

2. Don’t Skip the Certificate Passphrase (If Your PFX Has One)

You commented out host1.Ssl.CertPassphrase = "admin"; — if your .pfx file is password-protected (which 99% of production certificates are), you must uncomment this and use the correct password. Without it, the client can’t load the certificate, and the connection will fail silently (or with that unhelpful unreachable message).

3. Enforce a Modern TLS Version

RabbitMQ usually blocks older TLS versions like 1.0 or 1.1 by default for security. Uncomment and set the SSL version to TLS 1.2 (the minimum recommended for secure connections):

host1.Ssl.Version = System.Security.Authentication.SslProtocols.Tls12;

Stick to TLS 1.2 or higher unless your server is explicitly configured to allow older versions (you shouldn’t be using those anyway for compliance with security standards).

4. Clean Up Redundant Port Settings

You set connection.Port = 5671; and host1.Port = 5671; — this isn’t breaking anything, but it’s redundant. You can remove the top-level connection.Port line since you’re already defining the port in the HostConfiguration.

5. Double-Check Certificate Trust and File Access

Make sure:

  • The path C:\\tmp\\ProfileUnity.pfx is correct, and your application has read access to that file (if it’s running as a service, it might need explicit permissions to the tmp folder).
  • The RabbitMQ server’s certificate is installed in the Trusted Root Certification Authorities store on your client machine (not just the Current User store, if your app runs under a system account).
  • If your RabbitMQ setup requires mutual TLS (client certificate authentication), ensure your client cert is trusted by the server and has the right permissions.

Corrected Code Example

Here’s your code with all the key fixes applied:

var connection = new ConnectionConfiguration();
connection.UserName = "admin";
connection.Password = "****";
connection.Product = "YourClientAppName"; // Update this to your actual app name, not "localhost"
connection.VirtualHost = "StageDev";

var host1 = new HostConfiguration();
host1.Host = "skl-igor-naum1";
host1.Port = 5671;
host1.Ssl.Enabled = true;
host1.Ssl.ServerName = "skl-igor-naum1"; // Matches server cert CN/SAN
host1.Ssl.CertPath = "C:\\tmp\\ProfileUnity.pfx";
host1.Ssl.CertPassphrase = "admin"; // Uncommented with correct password
host1.Ssl.Version = System.Security.Authentication.SslProtocols.Tls12; // Enforce secure TLS

connection.Hosts = new List<HostConfiguration> { host1 };
connection.Validate();

MessageBusConnection = RabbitHutch.CreateBus(connection, services => 
    services.Register<IEasyNetQLogger>(logger => new DoNothingLogger()));

Extra Debugging Tips If You’re Still Stuck

  • Enable proper logging: Replace DoNothingLogger with a logger that outputs debug details (like the built-in ConsoleLogger). This will show you the actual SSL handshake error, which is way more useful than the vague "unreachable" message.
  • Test TLS with openssl: Run openssl s_client -connect skl-igor-naum1:5671 from your client machine. If this fails, the issue is with TLS setup, not your code.
  • Check RabbitMQ server logs: Look for TLS-related errors in the server logs when your client tries to connect — it might tell you exactly what’s wrong (like invalid client cert, mismatched CN, etc.).

内容的提问来源于stack exchange,提问作者user434774

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:17:56